Stack layer / Threat pattern
TrustShiftProbe: a compromised MCP server that behaves for N calls then defects hits 69.5% attack success, and the best defense only halves it
arXiv
Policy dependency / Threat pattern
mcp-shell Ships Security Off in One Deploy Path and Bypassable in the Other (CVE-2026-55580/55581/55582)
GitHub Security Advisories
Threat pattern / Contrast
48 threats catalogued against Google's Agent Payments Protocol v0.2, eight of them High severity, because signed mandates do not cover the pre-authorization context
arXiv
Stack layer / Update thread
Thomson Reuters Released Thomson-1.0-Small, a Law and Tax Model Built on Qwen3.6-35B-A3B
Hugging Face (thomsonreuters), via r/LocalLLaMA
Stack layer
Architecture Spec Format Barely Matters for Sonnet 4.6 and GPT-5, But Swings Weaker Models by up to 2.42 Points
arXiv 2608.21747
Stack layer
Hugging Face Detailed the Papers with Code Search Stack: PostgreSQL, pgvector and Qwen3-Embedding-0.6B
Hugging Face blog, via r/MachineLearning
Stack layer
Qwen3.8-Flash-Next Got a Release-Day Megathread and Unsloth Day-0 Quants Before the Weights Existed
r/LocalLLaMA megathread, weights at huggingface.co/Qwen/Qwen3.8-Flash-Next
Stack layer
AnTrap injects runtime anomalies into Android GUI agent trajectories and finds all 16 leading models degrade, with state deadlock unfixable by training
arXiv